niche-scout

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts to analyze Amazon niches based on user-supplied keywords. This is the intended functionality and uses standard argument passing.
  • [EXTERNAL_DOWNLOADS]: Fetches keyword volume and product metadata from DataForSEO and Apify's official API endpoints. These are established services for market research and the communication is purposeful and legitimate.
  • [DATA_EXFILTRATION]: API credentials for the research services are handled via environment variables and sent only to the respective service domains. No access to sensitive local files or untrusted network destinations was found.
  • [PROMPT_INJECTION]: The skill processes external content (book titles and publisher names) from Amazon search results. While this presents an indirect prompt injection surface, the risk is considered low due to the structured analysis and scoring benchmarks applied to the data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 03:30 PM
Security Audit — agent-trust-hub — niche-scout